Title: groups vs attributes

As our developers (as well as our 3rd party vendors) continue to create apps that leverage AD, the question comes up frequently which is a better solutionto search AD for a group membership, or for the value of a given attribute, when validating a users access to a custom application?

Our standard has been to use universal groups for this sort of thing, that is, UserA can access the application, if he is a member of the appropriate universal group. However, our developers have discovered in their ad hoc queries that returning a list of users that have a given value assigned to a custom attribute is much faster that returning a list of users that are members of a universal group. So they are asking, shouldnt we be adding a custom attribute when an application requires a validation that a user can access the application, rather than using a group membership?

Any notes from the field would be much appreciated!

Mark Creamer

Systems Engineer

Cintas Corporation

The Service Professionals

Reply via email to